Continuous Precision Deployment
Each hospital receives one isolated HMIS deployment. Production traffic follows Browser → Cloudflare (DNS/TLS/WAF) → host Nginx → PM2 on localhost (hmis-web :3000, hmis-api :4000), not direct PM2 ports on the public internet.
Edge before origin
Zone proxy
Public HTTPS terminates at Cloudflare before origin Nginx. Incident response may block ASNs at the edge (docs/info/policies/INCIDENT-RESPONSE-POLICY.md).
Turnstile
Public write routes use Cloudflare Turnstile (TURNSTILE_SECRET, NEXT_PUBLIC_TURNSTILE_SITE_KEY). Login stays rate-limited only.
Real client IP
Install infra/nginx/cloudflare-real-ip.conf so Nginx restores CF-Connecting-IP. Keep TRUST_PROXY=1 on the API.
API Shield (optional)
Upload api/openapi/openapi.cloudflare.json via npm run export:openapi-cloudflare for high-risk /api/v1 schema validation.
Cloudflare Tunnel, R2, and Workers are not documented as required HMIS production components unless your hospital adds them outside this repo.
Delivery pipeline
Validate
npm run test:deploy — TypeScript, drift guards, permission catalog, regression.
Synthesize
API + web builds, schema extract, app version codegen, Next.js staging swap.
Migrate
npx prisma migrate deploy — never rotate JWT/ENCRYPTION secrets casually.
Ignite
bash scripts/deploy-pm2.sh — PM2 api, worker, scheduler, web.
Operational commands
bash scripts/deploy-pm2.shCanonical production deploy from repo root
npm run test:deployFull deploy gate before release
npx prisma migrate deployApply pending schema migrations
pm2 statusInstance health and log tail
Runtime stack
PM2 on host; Docker Compose for Postgres, Redis, MongoDB, and observability on localhost
Application processes
- Node.js≥20 LTS (engines in package.json)
- OrchestrationPM2 cluster mode
- Processeshmis-api, hmis-worker, hmis-scheduler, hmis-web
- Origin proxyinfra/nginx/nginx.conf
Data plane
- OLTPPostgreSQL 16 (Compose)
- ChatMongoDB (Compose)
- Cache / jobsRedis + BullMQ
- MediaS3-compatible private buckets
- Pooling (optional)Compose pooler profile, PgBouncer :6432
Emergency shutdown
Enable disaster mode via governance settings and follow docs/info/policies/INCIDENT-RESPONSE-POLICY.md. Production deploy: bash scripts/deploy-pm2.sh from repo root.
Repository documentation
- docs/info/SECURITY-HARDENING.md
- docs/info/DR-PLAYBOOK.md
- docs/info/PERFORMANCE.md
- docs/info/OBSERVABILITY.md
- docs/info/SSO-OPERATIONS.md
- infra/README.md